Repository navigation
Merge pull request #4 from phireForge/main #3
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build script catalog | |
| # Keeps index.json - the catalog PaletteShell's in-palette "Browse community scripts" page | |
| # fetches - in sync with whatever is actually under scripts/. Contributors never touch | |
| # index.json themselves; it's generated by tools/Build-Index.ps1 and committed back by this | |
| # workflow after a merge to main. Pull requests only get a dry-run build, so a script that | |
| # fails to parse is caught before merge instead of silently breaking the catalog. | |
| on: | |
| push: | |
| branches: [main] | |
| paths: | |
| - "scripts/**" | |
| - "tools/Build-Index.ps1" | |
| - ".github/workflows/build-index.yml" | |
| pull_request: | |
| paths: | |
| - "scripts/**" | |
| - "tools/Build-Index.ps1" | |
| workflow_dispatch: {} | |
| permissions: | |
| contents: write | |
| # index.json itself is excluded from the path filters above, so the bot's own commit doesn't | |
| # retrigger this workflow - no [skip ci] dance needed. This concurrency group just protects | |
| # against overlapping runs from rapid consecutive pushes. | |
| concurrency: | |
| group: build-index-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| build-index: | |
| runs-on: ubuntu-latest | |
| steps: | |
| # Full history (not the default shallow depth-1 clone) - Build-Index.ps1 runs `git log` | |
| # per script to record each file's last-modified commit date, which needs the actual | |
| # history to be present, not just the tip commit. | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| # Manual runs are restricted to codeowners (.github/CODEOWNERS) - push-to-main and PR | |
| # validation builds are untouched by this and need no such check (push already requires | |
| # write access; PR builds are a read-only parse check open to any contributor). | |
| - name: Restrict manual runs to codeowners | |
| if: github.event_name == 'workflow_dispatch' | |
| env: | |
| ACTOR: ${{ github.actor }} | |
| run: | | |
| if ! grep -qiE "@${ACTOR}([[:space:]]|$)" .github/CODEOWNERS; then | |
| echo "::error::Manual runs of this workflow are restricted to codeowners. '${ACTOR}' is not listed in .github/CODEOWNERS." | |
| exit 1 | |
| fi | |
| - name: Build index.json | |
| shell: pwsh | |
| run: ./tools/Build-Index.ps1 | |
| - name: Check for changes | |
| id: diff | |
| run: | | |
| git add index.json | |
| if git diff --cached --quiet; then | |
| echo "changed=false" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "changed=true" >> "$GITHUB_OUTPUT" | |
| fi | |
| # Only push on a direct push to main with real write permissions - pull_request runs | |
| # (including ones from forks, which get a read-only token) are build-only validation. | |
| - name: Commit index.json | |
| if: github.event_name != 'pull_request' && steps.diff.outputs.changed == 'true' | |
| run: | | |
| git config user.name "github-actions[bot]" | |
| git config user.email "github-actions[bot]@users.noreply.github.com" | |
| git commit -m "Update index.json" | |
| git push |